Security Engineer 3

Oracle


Job Location:

Nashville, IN - USA

Yearly Salary: $ 82200 - 187000
Posted on: 10 days ago
Vacancies: 1 Vacancy

Job Summary

Description

Senior Security Engineer - Oracle Threat and Vulnerability Management

The Oracle Threat and Vulnerability Management (TVM) team proactively identifies assesses prioritises and relentlessly drives the remediation of security weaknesses and vulnerabilities at scale across the total enterprise. The TVM team performs security assessments vulnerability research guides and advises mitigation strategies and coordinates the response to zero-day and other urgent vulnerabilities. We ensure the security of the software and hardware that runs our cloud and non-cloud infrastructure and strive for continuous improvement. As a team we defend our customers and ensure Oracle meets or exceeds all applicable security and regulatory requirements in all markets.

Values our foundation and how we deliver excellence. We strive for equity inclusion and respect for all. We are committed to the greater good in our products and our actions. We are constantly learning and taking opportunities to grow our careers and ourselves. We challenge each other to stretch beyond our past to build our future. You can learn more about us by visiting you interested in building large-scale distributed security systems and tools for the cloud Do you enjoy all aspects of security from end user devices and traditional information technology (IT) to hyperscale cloud and multicloud services to hardware and operational technology (OT) A security-focused leader can have significant technical and business impact. This is a unique opportunity to work with smart people to solve complex and industry-wide problems in distributed systems security and multi-tenant Infrastructure-as-a-Service (IaaS) at massive scale.The biggest challenges for the team is the dynamic and fast growth of the business driving us to improve our systems tools and automation to scale to our security expertise several orders of magnitude greater than what we can support today. We understand that software is living and needs investment. The challenge is making the right tradeoffs communicating those decisions effectively and crisp execution. Come shape the future of one of the largest cloud services on earth with us!

Our ideal candidate is a hardworking security practitioner with interest in working in new domains and learning about new verticals every day. They should be fascinated with solving complex problems at the scale of a distributed multi-tenant service infrastructure.

This role is for a self-motivated individual interested and capable of managing multiple facets of security comfortable working as part of a global team and also independently as part of a larger security strategy.



Responsibilities

Responsibilities

  • Brings advanced-level skills to research evaluate track and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required and where computer programming/scripting knowledge is required.
  • Evaluates existing and proposed technical architectures for security risk provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks.
  • Evaluations of internal security architecture may include design assessment risk assessment and threat modelling.
  • Guides plans designs and oversees the implementation of new internal security architectures.
  • May participate in an incident management team bringing advanced-level skills to respond to security events and oversees root cause analysis.
  • Develops new methods and playbooks as well as sophisticated scripts applications and tools and trains others in their use.
  • Stay up-to-date on the latest advancements in cloud security and apply them to improve Oracles security posture.

Qualifications

  • 4 years of Software or systems engineering experience.
  • 2 years of cloud security experience.
  • Experience in evaluating and assessing security threats across a variety of environments and industries.
  • Knowledge of data structures algorithms operating systems and/or distributed systems fundamentals.
  • Understanding of secure networking principles routers switches and load balancers.
  • Understanding of databases NoSQL systems storage and/or distributed persistence technologies.
  • Knowledge of database security principles.
  • Knowledge of encryption technologies and architectures.
  • Prior experience with distributed systems cloud computing and IaaS.
  • Understanding of security vulnerabilities and mitigation strategies.
  • Programming and debugging fundamentals in languages/interfaces such as Python Java Go etc.
  • Experience automating tedious work using available application programming interfaces.

Preferred Qualifications

  • Hands-on experience developing or securing services on a public cloud platform (e.g. AWS Azure GCP OCI).
  • Industry certifications such as CISSP OSCP GIAC or equivalents
  • Proven ability to drive culture and behavioural change within engineering organisations.
  • Ability to effectively communicate and influence secure product and network design in a collaborative environment.
  • Experience driving multi-team initiatives tracking milestones and reporting status to leadership.
    Experience with security operations and security alert triage processes.
  • Knowledge of compliance program security controls like ISO/IEC 27001 SOC 2 PCI-DSS HITRUST FedRAMP and UK Cyber Essentials.
  • Knowledge of risk assessment frameworks like ISO/IEC 27005 ISO 31000 FAIR and NIST 800-30.
    Knowledge of incident response frameworks and methodologies including frameworks like NIST 800-61 and MITRE ATT&CK.
  • Experience building continuous integration/deployment pipelines with robust testing and deployment schedules.
  • Experience and understanding of cryptographic algorithms standards implementation and application.
  • Experience and understanding of threat modelling penetration testing reverse engineering and attacks on software.
  • Experience working in large complex global enterprise environments


Qualifications
Disclaimer:

Certain U.S. based or U.S. customer or client-facing roles may be required to comply with applicable requirements such as immunization/occupational health mandates and/or drug testing requirements.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $82200 to $187000 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge skills experience market conditions and locations as well as reflect Oracles differing products industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical dental and vision insurance including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

Career Level - IC3





Required Experience:

IC

DescriptionSenior Security Engineer - Oracle Threat and Vulnerability ManagementThe Oracle Threat and Vulnerability Management (TVM) team proactively identifies assesses prioritises and relentlessly drives the remediation of security weaknesses and vulnerabilities at scale across the total enterpris...

About Company

Company Logo

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity. We know that true innovation starts when eve ... View more

View Profile View Profile